有些IP的电脑无法访问A网站,有些无法访问B网站,访问速度时快时慢,请大神,帮我看看配置有没有问题。
防火墙F1020配置:
#
version 7.1.064, Release 9360P27
#
sysname H3C F1020
#
clock protocol none
#
context Admin id 1
#
telnet server enable
#
irf mac-address persistent timer
irf auto-update enable
irf auto-merge enable
undo irf link-delay
irf member 1 priority 1
#
security-policy disable
#
dialer-group 1 rule ip permit
dialer-group 2 rule ip permit
dialer-group 3 rule ip permit
dialer-group 4 rule ip permit
dialer-group 5 rule ip permit
dialer-group 6 rule ip permit
dialer-group 7 rule ip permit
dialer-group 8 rule ip permit
dialer-group 9 rule ip permit
dialer-group 10 rule ip permit
dialer-group 11 rule ip permit
dialer-group 12 rule ip permit
dialer-group 13 rule ip permit
#
ip unreachables enable
ip ttl-expires enable
#
dhcp enable
#
dns server 61.139.2.69
dns server 114.114.114.114
#
password-recovery enable
#
vlan 1
#
controller Cellular1/0/0
#
controller Cellular1/0/1
#
interface Bridge-Aggregation1
#
interface Route-Aggregation1
description connect to hexin
ip address 192.168.254.1 255.255.255.0
link-aggregation mode dynamic
#
interface Dialer1
mtu 1492
ppp chap password cipher $c$3$KnD7BYp+Gz76Vcr3YWTcVh61M7RAatYojagy
ppp chap user XXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXX password cipher $c$3$HD8FerVnnrXxr7um2ueKN2y9Wyn+LMLBLOo5
dialer bundle enable
dialer-group 1
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer2
mtu 1492
ppp chap password cipher $c$3$GNKl5RqvRuAYBk9GSnQA48Chks39GBRYgRIj
ppp chap user XXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXX password cipher $c$3$ccQiJT6OzxSHP5tsvlZ1SRJYV/b6qr2/0u7c
dialer bundle enable
dialer-group 2
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer3
mtu 1492
ppp chap password cipher $c$3$LBHAFh4japEe2HKeUR+S+nNhWyDkISguAKvF
ppp chap user XXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXX password cipher $c$3$rYHA2tcrkmkUoQwLISlxWEs9RV0ivVNj/5OB
dialer bundle enable
dialer-group 3
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer4
mtu 1492
ppp chap password cipher $c$3$SXz8Sb9Nz0D0aT4cbLOjtZqi+0BWnZpLvSHk
ppp chap user XXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXX password cipher $c$3$E/OpM93Rl/gyqca4y9W8FCAkG4EdBn4Y15HW
dialer bundle enable
dialer-group 4
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer5
mtu 1492
ppp chap password cipher $c$3$XyN+VetyqfkBZeDKrGxibV4SEqB+WFS984wq
ppp chap user XXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXX password cipher $c$3$8bfB4Iyc1wCpM4b3wfIHpYtTRyhPCcGGtNG7
dialer bundle enable
dialer-group 5
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer6
mtu 1492
ppp chap password cipher $c$3$Cuse1PS0ALOc4iBDyq05U6/d8g/zF0TNOb/a
ppp chap user XXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$gVdJWHsoEqTyY2J2Y3qOcA42lsW4CHR+rzPd
dialer bundle enable
dialer-group 6
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer7
mtu 1492
ppp chap password cipher $c$3$P8fsp3nR8CxyYY2zGkhmev6Fi6qkgctOQJi3
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$V/dsJuTIuCcDjF4OToceCk2iX2CN0FhxKjA7
dialer bundle enable
dialer-group 7
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer8
mtu 1492
ppp chap password cipher $c$3$gxsUE9h3GRfeEyu2idtR1PyaSm5JOYvpBqB8
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$ZoTEqCqrawED9eHF81jCosd68UC+ltyJ4tZ4
dialer bundle enable
dialer-group 8
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer9
mtu 1492
ppp chap password cipher $c$3$JJPPVhpcEaqiaKbw/g57iNJuAWSL9ssiMS36
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$Td1fbaMY3BhUqMWLtmchcdJDBgp0lNiB7VHk
dialer bundle enable
dialer-group 9
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer10
mtu 1492
ppp chap password cipher $c$3$CAu5OPIFKfIACmZKRjdp1+zXCDWTfcsQSB4j
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$2smFjVM2Bj65jQsGlU9YEJjkZEkHP4BHNNnI
dialer bundle enable
dialer-group 10
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer11
mtu 1492
ppp chap password cipher $c$3$vpD8iTR6tr7LDBoiP5FePZt/UMhD8CIoSBxM
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$3bJRU1IapT/65Z5kMUROprwJX6Oov+zb2lA7
dialer bundle enable
dialer-group 11
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer12
mtu 1492
ppp chap password cipher $c$3$lyB+7VpZ1J0oo2zKDwmQ7UEE7qkniyEgSlNV
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$mFprxevVMQaKY06+MEYES+vwjyIR15iJZi09
dialer bundle enable
dialer-group 12
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface Dialer13
mtu 1492
ppp chap password cipher $c$3$Lrf3DDlJpn2ycXQ0EHuTGSfkNSadsPh52B2J
ppp chap user XXXXXXX
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user XXXXXXX password cipher $c$3$anD7h6+TzPJUTb8cmCejd7EGOPPWicxHNirb
dialer bundle enable
dialer-group 13
dialer timer idle 0
ip address ppp-negotiate
tcp mss 1452
nat outbound
#
interface NULL0
#
interface Vlan-interface1
#
interface GigabitEthernet1/0/0
port link-mode route
ip address 192.168.0.1 255.255.255.0
#
interface GigabitEthernet1/0/1
port link-mode route
pppoe-client dial-bundle-number 1
#
interface GigabitEthernet1/0/2
port link-mode route
pppoe-client dial-bundle-number 2
#
interface GigabitEthernet1/0/3
port link-mode route
pppoe-client dial-bundle-number 3
#
interface GigabitEthernet1/0/4
port link-mode route
pppoe-client dial-bundle-number 4
#
interface GigabitEthernet1/0/5
port link-mode route
pppoe-client dial-bundle-number 5
#
interface GigabitEthernet1/0/6
port link-mode route
pppoe-client dial-bundle-number 6
#
interface GigabitEthernet1/0/7
port link-mode route
pppoe-client dial-bundle-number 7
#
interface GigabitEthernet1/0/8
port link-mode route
pppoe-client dial-bundle-number 8
#
interface GigabitEthernet1/0/9
port link-mode route
pppoe-client dial-bundle-number 9
#
interface GigabitEthernet1/0/10
port link-mode route
pppoe-client dial-bundle-number 10
#
interface GigabitEthernet1/0/11
port link-mode route
pppoe-client dial-bundle-number 11
#
interface GigabitEthernet1/0/12
port link-mode route
pppoe-client dial-bundle-number 12
#
interface GigabitEthernet1/0/13
port link-mode route
pppoe-client dial-bundle-number 13
#
interface GigabitEthernet1/0/14
port link-mode route
ip address 192.168.10.99 255.255.255.0
nat outbound 3000
#
interface GigabitEthernet1/0/15
port link-mode route
#
interface GigabitEthernet1/0/16
port link-mode route
#
interface GigabitEthernet1/0/17
port link-mode route
port link-aggregation group 1
#
interface GigabitEthernet1/0/18
port link-mode route
#
interface GigabitEthernet1/0/19
port link-mode route
port link-aggregation group 1
#
interface GigabitEthernet1/0/20
port link-mode route
#
interface GigabitEthernet1/0/21
port link-mode route
#
interface GigabitEthernet1/0/22
port link-mode route
#
interface GigabitEthernet1/0/23
port link-mode route
#
object-policy ip pass
rule 0 pass
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet1/0/15
import interface GigabitEthernet1/0/17
import interface GigabitEthernet1/0/19
import interface Route-Aggregation1
#
security-zone name DMZ
#
security-zone name Untrust
import interface Dialer1
import interface Dialer2
import interface Dialer3
import interface Dialer5
import interface Dialer6
import interface Dialer7
import interface Dialer8
import interface Dialer9
import interface Dialer10
import interface Dialer11
import interface Dialer12
import interface Dialer13
import interface GigabitEthernet1/0/1
import interface GigabitEthernet1/0/2
import interface GigabitEthernet1/0/3
import interface GigabitEthernet1/0/4
import interface GigabitEthernet1/0/5
import interface GigabitEthernet1/0/6
import interface GigabitEthernet1/0/7
import interface GigabitEthernet1/0/8
import interface GigabitEthernet1/0/9
import interface GigabitEthernet1/0/10
import interface GigabitEthernet1/0/11
import interface GigabitEthernet1/0/12
import interface GigabitEthernet1/0/13
import interface GigabitEthernet1/0/14
#
security-zone name Management
import interface GigabitEthernet1/0/0
#
zone-pair security source Local destination Trust
object-policy apply ip pass
#
zone-pair security source Trust destination Local
object-policy apply ip pass
#
zone-pair security source Trust destination Untrust
object-policy apply ip pass
#
scheduler logfile size 16
#
line class aux
user-role network-operator
#
line class console
authentication-mode scheme
user-role network-admin
#
line class vty
user-role network-operator
#
line aux 0
user-role network-admin
#
line con 0
user-role network-admin
#
line vty 0 4
authentication-mode scheme
user-role level-15
user-role network-admin
#
line vty 5 63
authentication-mode scheme
user-role network-admin
#
ip route-static 0.0.0.0 0 Dialer1 preference 70
ip route-static 0.0.0.0 0 Dialer2
ip route-static 0.0.0.0 0 Dialer3
ip route-static 0.0.0.0 0 Dialer4 preference 70
ip route-static 0.0.0.0 0 Dialer6 preference 80
ip route-static 0.0.0.0 0 Dialer7 preference 70
ip route-static 0.0.0.0 0 Dialer8 preference 80
ip route-static 0.0.0.0 0 Dialer9 preference 70
ip route-static 0.0.0.0 0 Dialer10 preference 80
ip route-static 0.0.0.0 0 Dialer11 preference 70
ip route-static 0.0.0.0 0 Dialer12 preference 80
ip route-static 0.0.0.0 0 Dialer13 preference 70
ip route-static 0.0.0.0 0 Dialer5 preference 70
ip route-static 10.0.0.0 8 192.168.10.1
ip route-static 192.168.11.0 24 192.168.254.2
ip route-static 192.168.80.0 24 192.168.254.2
#
performance-management
#
ssh server enable
#
arp ip-conflict log prompt
#
acl advanced 3000
rule 0 permit ip source 192.168.80.192 0.0.0.63 destination 10.0.0.0 0.255.255.255
rule 20 deny ip
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
password hash $h$6$xsJgx1I7v33nUvtU$sKe9bTx1uuvkOMy/xwu34iRRRZNPcAdqptMwal0gZaTyxgjDSWEEhpG/OtZiMdQKMWGeFaDbFhh8vxaVhpZsrg==
service-type ssh telnet terminal https
authorization-attribute user-role level-3
authorization-attribute user-role level-15
authorization-attribute user-role network-admin
authorization-attribute user-role network-operator
#
ipsec logging negotiation enable
#
ike logging negotiation enable
#
ip http enable
ip https enable
#
loadbalance isp file flash:/lbispinfo_v1.5.tp
#
cloud-management server domain opstunnel-seccloud.h3c.com
#
return
(0)
部分无法访问网站:
1、检查dns是否能解析,解析不了,看dns问题
2、能解析,跟踪路由,看IP卡在哪一跳
(0)
DNS都是本地营运商的,都没问题
内网配置没啥问题啊,
全是拨号的宽带?
建议一条一条试,测试出哪些宽带无法访问A,哪些无法访问B,哪些宽带A、B都可以访问。
然后写策略路由,把A、B两个网站都抛给某条或某几条(这条宽带A、B都可以访问),
(0)
甲方全是拨号宽带,宽带都是正常的
我把F1020换下,换上一台ER8300G2-X 一点问题都没有,用F1020就有不稳定的情况。
但是8300只有5wan口
在dialer接口下修改tcp mss为1200试一下
(0)
我去尝试一下
我去尝试一下
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
DNS都是本地营运商的,都没问题